No mailbox provider changed the rules this week. Instead the story is your own infrastructure: Roundcube shipped eleven security fixes without a single CVE number, and within 48 hours Check Point published research showing North Korea's Lazarus group running command-and-control through compromised Roundcube servers. Those two items are the same story told from opposite ends.
Underneath that, the money layer moved — Klaviyo's Q2 numbers show what email platform economics actually look like in 2026, LiveRamp's shareholders voted on a $2.5B exit to Publicis, and Intuit's own guidance quietly names Mailchimp as the drag. Lighter week than last. Let's get into it.
Roundcube released 1.6.18 (LTS) and 1.7.3 on August 9 with identical security payloads, and the contents are not minor. There's a remote code execution path in the bundled markasjunk plugin's cmd_learn driver, reported by nept1337. There's an IMAP command injection via mail search that abuses LITERAL+ byte-count desynchronisation and reaches a pre-authentication stage — reported by Zach Hanley, chief attack engineer at Horizon3.ai. Then SSRF bypasses abusing NAT ranges and hostname services, LDAP filter injection, Sieve script injection, and XSS in address book and content handling.
Eleven issues. Zero CVE identifiers assigned to any of them. That's a break from July's release, which carried CVE-2026-54432 and CVE-2026-54433.
Here's why that matters more than the bug list: with roughly two million internet-exposed Roundcube deployments, "no CVE" means your automated scanner sees nothing. Your compliance dashboard reports zero open findings. The gap between a patch existing and a patch being identifiable is a free window, and attackers don't need the identifier to find the diff. Compounding it — cPanel bundles Roundcube across a large share of shared hosting and historically trails upstream by 5–9 days, so hosting providers are choosing between waiting and patching by hand.
Roundcube is now shipping roughly one security release a month. If your webmail maintenance window is still quarterly, you're not running a patch cadence — you're running a countdown.
Sources: Roundcube security releases, webhosting.today, Cybersecurity News, SSD advisory (markasjunk RCE)
Sponsored

KumoMTA: Open-Source email infrastructure for enterprises & high-volume senders
KumoMTA gives MailOps teams full control on their terms. Manage routing, policy, queues, deliverability, and infrastructure. Deploy in the cloud or on-premises, scale with Docker and Kubernetes, automate with Lua, integrate with existing tooling, and grow without the risk, volatility, or pricing shocks that come with proprietary platforms.
Founded by engineers who built, operated, and supported the platforms behind billions of daily emails, KumoMTA delivers the performance to send tens of millions of messages per hour on a single instance.
Beyond the platform, KumoMTA is backed by a global community of developers, security researchers, and enterprises, and offers enterprise-grade support and professional services for organizations that want a trusted partner.
Try KumoMTA for freeCheck Point Research published on August 11 on a 2026 wave of Operation Dream Job, the DPRK-linked Lazarus campaign aimed at defence, aerospace, and aviation firms. The lure is email: targeted spear-phishing built around attractive job offers, impersonating real companies — privacy-tech firm Enveil among them — leading to an encrypted ZIP containing a trojanised PDF viewer called "SecurityPDF." A second chain uses DLL sideloading. The group also stood up impersonation websites and used SEO to make the trojanised downloads look organic, specifically to route around phishing-based detection.
Post-exploitation they deployed a new FudModule rootkit build via CVE-2026-68820, a zero-day race condition in the Windows AFD.sys driver that yields SYSTEM privileges and blinds EDR. Microsoft patched it on August 11 — the same Patch Tuesday as the Exchange updates.
The email-industry detail is the one to sit with: the C2 infrastructure runs on compromised Roundcube webmail servers (and WordPress hosts) still unpatched against CVE-2025-49113, hosting a new PHP webshell called RelayShell that turns them into relay nodes.
Unpatched webmail isn't just a mailbox-compromise risk anymore. It's being conscripted as espionage infrastructure. Which means "there's nothing sensitive in that mailbox" has stopped being a reason to defer the update — the mail on the box was never what they wanted.
Sources: Check Point Research, Help Net Security, Security Affairs
(Disclosure: I work at Klaviyo. Everything below is from the public earnings call and press releases, and the read is mine.)
Klaviyo reported Q2 on August 5, with the call transcript out August 12: revenue $370.6M, up 26% year over year, net revenue retention 109%, customers above $50K ARR up 36% to 4,477, total customers past 205,000, international revenue up 35%. The uncomfortable line is further down the page — non-GAAP gross margin 73.4%, down three points year over year, explicitly attributed to growth in text messaging and higher carrier fees.
Management also cut the midpoint of full-year non-GAAP operating income guidance by $10M, citing $10–12M in costs from the Agency acquisition announced the same day: the team and technology behind Elias Torres's AI-native customer success startup (25 people, $32M raised from Sequoia, Menlo, Felicis). Torres becomes Chief Product Officer over the agent product line. The deal closes in Q3, and Agency's standalone product is being wound down August 31.
The vendor-neutral read: this is one of the few pure-play public windows into the market, and what it shows is growth being bought with lower-margin channels while the strategic spend goes to AI agents. Email is the profitable base funding all of it and gets the least airtime — the same shape as Twilio not mentioning SendGrid, which we covered last issue.
There's a smaller lesson buried in the acqui-hire too, and it's the one to take personally: if you were an Agency customer, your product dies in two weeks.
Sources: Q2 earnings call transcript, Agency acquisition, TechCrunch, product wind-down
DKIM2 is closing in on Q4 experimental mode. Three working-group drafts are now in flight: draft-ietf-dkim-dkim2-spec-04, draft-ietf-dkim-dkim2-bcp-00 (Best Practices, authored by Todd Herr of GreenArrow Email, adopted June 18), and draft-ietf-dkim-dkim2-dns-00, the DNS record spec adopted July 20. The IESG separately rechartered the DMARC working group in April for the sole purpose of moving RFC 8617 (ARC) to Historic. Reporting suggests major mailbox providers intend to run DKIM2 in experimental mode in Q4 — verifying signatures and surfacing results in DMARC aggregate reports, which means you'd see it in your own data before any vendor roadmap mentions it. Nothing to change in production today. Read the drafts, take the CSA webinar on the 25th, don't touch prod. Spec · BCP draft · DNS draft explainer
328 out of 7,000. Following last issue's coverage of Cory Solovewicz's misdirected-mail research, Al Iverson put hard numbers on it August 15: 401,796 messages to a single placeholder domain since December 2024 (roughly 700/day), 28,365 of them carrying attachments, arriving from more than 14,000 From addresses across 6,200 root domains. The new figure that reframes it — Solovewicz tested more than 7,000 candidate placeholder domains and found 328 already configured with catch-all inboxes. Iverson runs similar domains himself and sees 600+ misdirected messages a day, mostly from major brands. Every From and Reply-To domain your program has ever used is a permanent liability. Spam Resource
LiveRamp shareholders voted August 17 on Publicis Groupe's all-cash acquisition at $38.50/share — $2.5B equity value, a 30% premium to the May 15 close. Approval needed two-thirds of outstanding shares; close is expected by the end of calendar 2026. LiveRamp's identity graph sits underneath a lot of audience matching and onboarding that email programs quietly depend on, and folding it into an agency holding company raises the neutrality question worth asking about any dependency: does your plumbing now have a parent with its own media interests? ppc.land · Publicis announcement
Cisco Talos dissected JWR, a phishing-as-a-service framework hitting banking and payment customers that holds an AES-CTR-encrypted WebSocket open to a human operator — so an attacker watches the victim type in real time and pushes tailored login, payment, and verification pages to harvest cards, credentials, ID documents, and OTPs. Lures observed across Singapore, the UAE, and wider SEA/Middle East. Talos assesses with medium confidence it's a variant of Outsider, the PhaaS platform the FBI hit in Operation Ghost Hook in June. Outsider was sold self-service through Telegram, so variants keep circulating post-takedown. Live operator involvement defeats OTP as a control outright — assume a code can be relayed within seconds of delivery. Talos
Exchange Server's August SU killed OWA Light, and the EWS deadline is 12 days out. Following up on last issue: the August 11 Exchange Server security updates disable OWA Light by default, silently redirecting users to standard Outlook on the web. The Exchange Online EWS allow-list deadline stands at August 31 — tenants that set EWSEnabled=True and configure an AppID allow list before month-end are excluded from the October 1 automatic flip to EWSEnabled=False. Shared calendar migration to the modern REST model is also rolling through late September. Exchange Team Blog · EWS deadline
Intuit's own guidance names Mailchimp as the drag. Global Business Solutions is projected to grow 14–15% for 2026 — but 15.5–16.5% excluding Mailchimp. Management has confirmed Mailchimp revenue declined year over year while the rest of the small-business portfolio grew double digits, and as of January the product was flat at 11 million users, 0% growth since mid-2024, against MailerLite +52%, Omnisend +50%, HubSpot +29%, Klaviyo +28%, Brevo +20%. When a parent quantifies in guidance how much faster it grows without your product, plan your migrations on that number, not on a roadmap slide. emailexpert
CU Boulder shuts off alumni "email for life" on August 31. Existing alumni lose their university-provided address; new graduates keep colorado.edu for one year post-graduation only. The university cites licensing costs, declining usage, dormant-account security risk, and compliance burden. Data won't be recoverable after the cutoff. Universities retiring lifetime addresses is a slow-motion source of hard bounces on any list carrying alumni, donor, or education cohorts — and it's invisible until the bounces land. If you hold .edu addresses acquired more than a few years back, that's a re-permissioning prompt, not a hygiene chore. CU Boulder OIT
Stalwart shipped v0.16.18 on August 17 — reporting size bounds, RocksDB cache management, and fixes to JMAP identity sync, calendar, WebDAV, and IDN handling. (v0.16.17 on August 10 added the UIDBATCHES, UIDONLY, and MESSAGELIMIT/SAVELIMIT IMAP extensions plus WebDAV range requests.) Releases
Ask Al: how to actually set up a BIMI logo. Iverson's August 18 video walks the implementation, not the theory. Pairs with his earlier explainer on what "self-asserted" means. If you're at DMARC enforcement and haven't taken the last step, this is the twenty minutes. Spam Resource
Costco CEMA settlement — claims and exclusions close August 24. Final approval hearing is October 2. Deadline reminder only, no new development. Details
Confirmed live this week, deliverability and infrastructure roles at email-industry companies first:
Also open on the development and ops side: Vivian Health, OnePay, CoStar (Homes.com), Blue Shield of California, Texas Health Resources (SFMC lead), Bell, Carnival, Global Payments, Walmart Data Ventures, the Minnesota Star Tribune, NAR, kate spade new york, and Suitsupply.
That's the week. Patch the webmail box you forgot you were running, check whether your scanner would have told you to, and go read the DKIM2 drafts before someone asks you about them on a call.
As always, I'd love your feedback. Hit "reply" and tell me what I got wrong — I read every response. Better yet, hit "forward" and send this to the person on your team who owns the mail servers.
— John
This Week In Email — thisweekin.email
Subscribe to This Week in Email and get future issues delivered to your inbox.